<div dir="ltr">alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET 
CURRENT_EVENTS W32/Zbot Download Invoice Spam Campaign 10th Sep 2014"; 
flow:established,to_server; content:"/Invoice_"; nocase; http_uri; 
depth:9; content:".exe"; http_uri; 
pcre:"/^\x2FInvoice\x5F\d{5,}\x2Eexe$/Ui"; classtype:trojan-activity; 
reference:md5,bdf12366779ce94178c2d1e495565d2b; sid:1239991; rev:1;)<br><div><br><br></div>Kind Regards,<br>Kevin Ross</div>